Cybersecurity

How to Protect Your Brand from Typosquatting and Domain Spoofing

A practical playbook for defending your brand against typosquatting: which variants to register, how to monitor for new lookalikes, and the legal levers (UDRP, URS, trademark) that actually get a bad domain taken down.

By Inventive HQ Team

Typosquatting is the registration of deliberately misspelled or lookalike versions of a legitimate domain — gooogle.com, paypa1.com, micros0ft.com — to intercept mistyped traffic, run phishing, or damage a brand. You defend against it with a three-layer program: (1) defensively register a tight core set of high-risk variants (exact-match in .com/.net/.org and your ccTLD, plus the one or two most common typos and any pixel-identical homoglyph twin); (2) monitor the rest continuously — Certificate Transparency logs surface new lookalikes within seconds of a certificate being issued, days before they send mail; and (3) take down weaponized domains through UDRP (transfers the domain, ~$1,500, 2–3 months), URS (suspends it, ~$375, faster), or a registrar abuse notice when active phishing is involved.

That is the summary an AI Overview can give you. What it can't show you is the shape of the problem — how many variants a single brand actually spawns, which of the dozens of attack types matters, and the decision path from "I found a lookalike" to "it's gone." The diagram, the live analyzer, and the tables below make that concrete.

The problem is bigger than it looks: one brand, hundreds of variants

Every brand name is the seed of a large lookalike space. Attackers don't guess randomly — they work through a small number of well-known transformation classes, and each class multiplies with the others and with the ~1,500 available TLDs. The figure below shows how a single seven-letter brand fans out.

How one brand name fans out into hundreds of typosquatting variants A central brand domain branching into six transformation classes — omission, duplication, adjacent-key swap, transposition, homoglyph substitution, and alternate TLD — each showing an example lookalike domain. acmebank.com Six transformation classes, one seed Omission acmbank.com
<rect x="30" y="160" width="180" height="40" rx="5" fill="#ffffff" stroke="#e2e8f0"/>
<text x="120" y="178" text-anchor="middle" font-weight="700">Duplication</text>
<text x="120" y="193" text-anchor="middle" fill="#b91c1c">accmebank.com</text>

<rect x="30" y="250" width="180" height="40" rx="5" fill="#ffffff" stroke="#e2e8f0"/>
<text x="120" y="268" text-anchor="middle" font-weight="700">Adjacent key</text>
<text x="120" y="283" text-anchor="middle" fill="#b91c1c">acnebank.com</text>

<rect x="550" y="70" width="180" height="40" rx="5" fill="#ffffff" stroke="#e2e8f0"/>
<text x="640" y="88" text-anchor="middle" font-weight="700">Transposition</text>
<text x="640" y="103" text-anchor="middle" fill="#b91c1c">acembank.com</text>

<rect x="550" y="160" width="180" height="40" rx="5" fill="#ffffff" stroke="#e2e8f0"/>
<text x="640" y="178" text-anchor="middle" font-weight="700">Homoglyph</text>
<text x="640" y="193" text-anchor="middle" fill="#b91c1c">аcmebank.com</text>

<rect x="550" y="250" width="180" height="40" rx="5" fill="#ffffff" stroke="#e2e8f0"/>
<text x="640" y="268" text-anchor="middle" font-weight="700">Alternate TLD</text>
<text x="640" y="283" text-anchor="middle" fill="#b91c1c">acmebank.co</text>

6 classes × common substitutions × ~1,500 TLDs = hundreds of plausible lookalikes per brand

The takeaway: you cannot register your way out of this. Defensive registration is a containment tactic for the highest-risk handful; monitoring and takedown handle the long tail.

See it live: analyze a domain or generate protective variants

The tool below runs the same transformations an attacker would. Enter a suspicious domain to score its visual and structural similarity to a brand, or enter your own domain to generate the protective-variant list worth registering or watching.

Loading interactive tool...
Advertisement

The defense workflow, end to end

Brand protection against typosquatting is a loop, not a one-time purchase. Each stage feeds the next.

The four-stage typosquatting defense loop A continuous cycle: Enumerate variants, Register the core set, Monitor for new lookalikes, then Take down weaponized domains, feeding back into monitoring. Continuous defense loop 1. Enumerate map the variant space
<rect x="210" y="70" width="160" height="70" rx="8" fill="#ffffff" stroke="#2813e8" stroke-width="2"/>
<text x="290" y="100" text-anchor="middle" fill="#0f172a" font-weight="700">2. Register</text>
<text x="290" y="120" text-anchor="middle" fill="#334155" font-size="11">core set only</text>

<rect x="400" y="70" width="160" height="70" rx="8" fill="#ffffff" stroke="#2813e8" stroke-width="2"/>
<text x="480" y="100" text-anchor="middle" fill="#0f172a" font-weight="700">3. Monitor</text>
<text x="480" y="120" text-anchor="middle" fill="#334155" font-size="11">CT logs + WHOIS</text>

<rect x="590" y="70" width="160" height="70" rx="8" fill="#ffffff" stroke="#f59e0b" stroke-width="2"/>
<text x="670" y="100" text-anchor="middle" fill="#0f172a" font-weight="700">4. Take down</text>
<text x="670" y="120" text-anchor="middle" fill="#334155" font-size="11">UDRP / URS / abuse</text>
takedowns feed new detection patterns back into monitoring

Which variants to register vs. monitor

Defensive registration is a budget decision. Buy the variants where the cost of not owning them is a live phishing site; monitor the rest.

Variant typeExampleRegister or monitor?Why
Exact match, top TLDsacmebank.net, acmebank.orgRegisterCheap insurance; these are the first ones attackers grab
Your country ccTLDacmebank.co.uk, acmebank.deRegisterRegional customers assume it exists
Homoglyph twin (reads identically)аcmebank.com (Cyrillic а)Register if availablePixel-identical in some fonts; highest phishing value
Top 1–2 fat-finger typosacmbank.com, acmebnak.comRegisterCatches real mistyped traffic and denies the obvious lure
Long-tail typosacmebankk.com, acmeban.comMonitorHundreds of these; only act if weaponized
Combo-squatsacmebank-login.com, secure-acmebank.comMonitorInfinite space; watch CT logs and act on active abuse
Alternate new gTLDsacmebank.bank, acmebank.xyzDependsRegister .bank (restricted, trust signal); monitor speculative gTLDs
Which should I use?Register the top ~10–20, monitor the restRegistration is O(handful); monitoring is O(everything)

What "weaponized" means — the takedown triggers

A registered lookalike sitting on a parking page is annoying, not urgent. Escalate when you see any of these:

SignalWhat it meansResponse
MX records configuredThe domain can send/receive mail — spoofing setupPrepare takedown; warn staff/customers
A login/checkout page cloning your brandActive credential phishingRegistrar + host abuse notice now; URS if new gTLD
A TLS certificate issued for the lookalikeSomeone is standing up HTTPS — usually pre-launchWatch closely; certificate is your early warning
Ads or redirects to competitorsRevenue diversion / brand dilutionUDRP for transfer; ACPA claim if in the U.S.
WHOIS shows bulk registration by one partyOrganized cybersquatterBundle multiple domains into one UDRP complaint
MechanismCostTimeOutcomeBest for
Registrar/host abuse noticeFreeHours–daysSuspensionActive phishing with clear harm
URS (Uniform Rapid Suspension)~$375~3 weeksSuspends (no transfer)Clear-cut abuse in new gTLDs
UDRP (via WIPO/Forum)~$1,500+2–3 monthsTransfer or cancelTrademark cases where you want the domain
ACPA lawsuit (U.S.)Legal feesMonths+Damages + transferEgregious/repeat cybersquatters, $1k–$100k statutory damages per domain

Rule of thumb: active phishing → abuse notice first (fastest harm reduction). Want the domain permanently → UDRP. Just want it dead in a new gTLD → URS.

Monitor with Certificate Transparency, not just WHOIS

The single highest-leverage monitoring source is Certificate Transparency. Because browsers require CT-logged certificates and nearly every phishing site now uses HTTPS, the attacker publishes their lookalike domain to a public, append-only log the moment they request a certificate — typically before the phishing page is even finished. Watching CT logs for your brand string gives you a lead time WHOIS-based monitoring can't match. Pair it with DMARC (p=reject) so exact-domain spoofing is blocked at the same time you're hunting lookalikes.

Enumerate your own exposure

To see the full variant space for your domain and check which lookalikes are already registered across every TLD, use our TLD Enumerator. Combine it with the Domain Spoofing Detector above to score how convincing each lookalike would be to a human.

Bottom line

You can't register every misspelling — the math doesn't allow it. Win instead by containing the highest-risk handful with defensive registration, watching Certificate Transparency for everything else, and having a rehearsed escalation path (abuse notice → URS → UDRP) so that when a lookalike goes hot, it's offline before it costs you a customer.

Frequently Asked Questions

What is typosquatting?

Typosquatting (also called URL hijacking) is registering domains that are deliberate misspellings or near-lookalikes of a legitimate brand — for example gooogle.com, paypa1.com, or micros0ft.com — to intercept mistyped traffic, run phishing, serve ads, or damage a brand's reputation. It is a subset of cybersquatting that specifically exploits human typing and reading errors.

How many typo variants of my domain exist?

More than most people expect. A single seven-character brand generates hundreds of plausible variants once you combine character omission, duplication, adjacent-key swaps, transposition, homoglyph substitution (rn→m, 0→o, l→1), and alternate TLDs (.co, .cm, .net, .org). Tools like dnstwist or our TLD Enumerator enumerate the space so you can see which variants are already registered and by whom.

Should I defensively register every typo of my domain?

No — that is financially unbounded and unnecessary. Register a tight core set: the exact-match in high-risk TLDs (.com, .net, .org, your ccTLD), the one or two most common fat-finger typos, and any homoglyph twin that reads identically. Monitor everything else and act only when a lookalike is actually weaponized (mail records, a login page, or active phishing).

What is a homoglyph or homograph attack?

A homograph attack uses characters that look identical but are different code points — most commonly Cyrillic 'а' (U+0430) standing in for Latin 'a', or the rn/m and 0/o substitutions. Registered as an internationalized domain name, the address can appear pixel-identical to the real one in some fonts. Browsers defend by displaying mixed-script IDNs in Punycode (xn--), but email clients and link previews often do not.

How do I get a typosquatted domain taken down?

You have three escalating options. File a UDRP complaint with a provider like WIPO (about $1,500 in fees, 2–3 months, transfers or cancels the domain). Use the faster, cheaper URS for clear-cut abuse in newer gTLDs (about $375, suspends but does not transfer). Or send an abuse/DMCA notice to the registrar and hosting provider, which often works within days when active phishing is involved.

What is the difference between UDRP and URS?

UDRP (Uniform Domain-Name Dispute-Resolution Policy) can transfer or cancel a domain and applies to all gTLDs, but costs more and takes 2–3 months. URS (Uniform Rapid Suspension) is a lightweight version for clear-cut cases in new gTLDs: it is faster and cheaper but only suspends the domain for the remaining registration period — it does not transfer it to you.

Can DMARC stop typosquatting?

DMARC only protects your exact sending domain from spoofing — it does not stop attackers using a lookalike domain they own. A p=reject DMARC policy stops mail claiming to be from yourbrand.com, but does nothing about yourbránd.com, which passes its own SPF/DKIM legitimately. You need both: DMARC for exact-domain spoofing and monitoring/takedown for lookalikes.

How quickly can I detect a new typosquatted domain?

Near real-time if you watch Certificate Transparency logs. Almost every lookalike domain used for phishing gets a TLS certificate before it goes live, and every issued certificate is published to public CT logs within seconds. Monitoring CT for your brand string catches new lookalikes days before they send a single email — often before the attacker has finished building the phishing page.

Is typosquatting illegal?

Registering a confusingly similar domain in bad faith to profit from a trademark is unlawful under the U.S. Anticybersquatting Consumer Protection Act (ACPA) and actionable under ICANN's UDRP worldwide. Statutory damages under ACPA run from $1,000 to $100,000 per domain. Note that registering a generic misspelling with no bad-faith intent to trade on a mark is a weaker case.

typosquattingbrand protectiondomain securityUDRPtrademark